CVE-2026-3977 Details
Description
A security vulnerability has been detected in projectsend up to r1945. The affected element is an unknown function of the component AJAX Endpoints. The manipulation leads to missing authorization. The attack can be initiated remotely. The identifier of the patch is 35dfd6f08f7d517709c77ee73e57367141107e6b. To fix this issue, it is recommended to deploy a patch.
A vulnerability exists in ProjectSend versions up to r1945, where certain AJAX endpoints lack proper authorization checks. This issue allows any authenticated user, including clients with the lowest role level, to access restricted functions. The vulnerability was introduced by not verifying if the user had the necessary permissions before executing actions that should be restricted to higher-level users. As a result, it could lead to unauthorized file enumeration and deletion of custom download links.
Users are advised to update to the latest version of ProjectSend, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 12, 2026CISA-ADP
Assessed Mar 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/projectsend/projectsend/ | [email protected] | Vendor |
| https://github.com/projectsend/projectsend/commit/35dfd6f08f7d517709c77ee73e57367141107e6b | [email protected] | Source CodeVendor |
| https://github.com/projectsend/projectsend/issues/1525 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/projectsend/projectsend/issues/1525#issuecomment-3957109914 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://vuldb.com/?ctiid.350412 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.350412 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ProjectSend | <= r1945 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 12, 2026 | New CVE Received | [email protected] |
Volerion